A AegiFlow
MEDIUMCVSS 5.4EPSS 0.2%

CVE-2026-21724

Grafana OSS: Authorization bypass allows users with Editor role to modify protected webhook URLs without permissions

Published
2026-03-26
Modified
2026-07-21
EPSS percentile
15%
Aliases
GHSA-7g92-g4vh-hp84
Sources
github-advisory

Summary

A vulnerability has been discovered in Grafana OSS where an authorization bypass in the provisioning contact points API allows users with Editor role to modify protected webhook URLs without the required alert.notifications.receivers.protected:write permission. A patched version is available at https://github.com/grafana/grafana/releases/tag/v12.3.6.

Affected packages

EcosystemPackageAffected versionsFixed versions
Gogithub.com/grafana/grafana1.9.2-0.20260323180334-daffe750de85

Remediation: Upgrade to 1.9.2-0.20260323180334-daffe750de85 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.